logo

Expel Quarterly Threat Report Q3 2024, volume IV: Suspicious infrastructure from phishing-as-a-service (PhaaS) platforms

ID: 91ce0426-4675-5e0d-b553-6861f82cb8b0

STIX ID: report--91ce0426-4675-5e0d-b553-6861f82cb8b0

Feed Name: Expel Blog

Threat Score
60/100

Date Published: 2024-10-23

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

This Volume IV threat report examines the rise of phishing-as-a-service (PhaaS) driving identity-based incidents in Q3 2024, noting that authentications from hosting/VPS providers (suspicious infrastructure) rose to 51% of identity incidents. The authors identify three recurring PhaaS platforms (Tycoon 2FA, Rockstar/Dadsec, JSNOM), describe observable indicators (phishing email patterns, credential harvester styles, hosting providers), and recommend enriching anomalous-authentication alerts with hosting-provider checks and cross-customer pattern analysis to detect and mitigate these campaigns earlier.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.